Giovanni Mazzeo

dblp:184/1720 · DBLP profile ↗
← Back
21ranked-venue papers
1as first author
10since 2021 · last 2026
0000-0002-0238-5616ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Systems, architecture and hardware · 2 · 1 since 2021Computer networks · 2 · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 2
YearPublicationVenuePosition
2026 EigenFL: An EigenLayer-Restaked Blockchain Solution for Secure Federated Learning
Giovanni Maria Cristiano, Salvatore D'Antonio, Giovanni Mazzeo
COMPSAC3
2025 An experimental evaluation of TEE technology: Benchmarking transparent approaches based on SGX, SEV, and TDX
abstract
Protection of data-in-use is a key priority, for which Trusted Execution Environment (TEE) technology has unarguably emerged as a — possibly the most — promising solution. Multiple server-side TEE offerings have been released over the years, exhibiting substantial differences with respect to several aspects. The first comer was Intel SGX, which featured Process-based TEE protection, an efficient yet difficult to use approach. Some SGX limitations were (partially) overcome by runtimes, notably: Gramine , Scone , and Occlum . A major paradigm shift was later brought by AMD SEV, with VM-based TEE protection, which enabled ”lift-and-shift” deployment of legacy applications. This new paradigm has been implemented by Intel only recently, in TDX. While the threat model of the aforementioned TEE solutions has been widely discussed, a thorough performance comparison is still lacking in the literature. This paper provides a comparative evaluation of TDX , SEV , Gramine-SGX , and Occlum-SGX . We study computational overhead and resource usage, under different operational scenarios and using a diverse suite of legacy applications. By doing so, we provide a reliable performance assessment under realistic conditions. We explicitly emphasize that — at the time of writing — TDX was recently released to the public. Thus, the evaluation of TDX is a unique feature of this study.
Luigi Coppolino, Salvatore D'Antonio, Giovanni Mazzeo, Luigi Romano
Comput. Secur.3
2025 The good, the bad, and the algorithm: The impact of generative AI on cybersecurity
abstract
Generative Adversarial Networks (GANs) are emerging as a transformative technology in cybersecurity, presenting both opportunities and challenges in enhancing defensive and offensive strategies. This paper explores the impact that Generative Artificial Intelligence (AI) has on cybersecurity, focusing on its application in the field of network and web security. Current research reveals robust defensive approaches; however, there remains a significant gap in the application of Generative AI to develop advanced attack scenarios capable of bypassing existing defense mechanisms. Our work attempts to fill this gap and spreads awareness regarding a potential exposure of Neural Network (NN)-based Intrusion Detection Systems (IDSs) against AI-enhanced attacks. Unlike conventional approaches that focus on Input Perturbation, Data Poisoning, or Spoofing, we propose a novel offensive strategy called Attack Obfuscation. This strategy leverages Conditional GANs (CGANs) to conceal genuine attacks by injecting synthetic traffic designed to deceive NN-based IDS. The experimental investigation validates the proposed approach against three distinct datasets and different typologies of attacks, managing to successfully deceive the IDS.
Luigi Coppolino, Salvatore D'Antonio, Giovanni Mazzeo, Federica Uccello
Neurocomputing3
2024 A Comprehensive Trusted Runtime for WebAssembly With Intel SGX
abstract
In real-world scenarios, trusted execution environments (TEEs) frequently host applications that lack the trust of the infrastructure provider, as well as data owners who have specifically outsourced their data for remote processing. We presentTwine, a trusted runtime for running WebAssembly-compiled applications within TEEs, establishing a two-way sandbox.Twineleverages memory safety guarantees of WebAssembly (Wasm) and abstracts the complexity of TEEs, empowering the execution of legacy and language-agnostic applications. It extends the standard WebAssembly system interface (WASI), providing controlled OS services, focusing on I/O. Additionally, through built-in TEE mechanisms,Twinedelivers attestation capabilities to ensure the integrity of the runtime and the OS services supplied to the application. We evaluate its performance using general-purpose benchmarks and real-world applications, showing it compares on par with state-of-the-art solutions. A case study involving fintech companyCredorareveals thatTwinecan be deployed in production with reasonable performance trade-offs, ranging from a 0.7× slowdown to a 1.17× speedup compared to native run time. Finally, we identify performance improvement through library optimisation, showcasing one such adjustment that leads up to$4.1\times$speedup.Twineis open-source and has been upstreamed into the original Wasm runtime, WAMR.
Jämes Ménétrey, Marcelo Pasin, Pascal Felber, Valerio Schiavoni, Giovanni Mazzeo, Arne Hollum, Darshan Vaydia
IEEE Trans. Dependable Secur. Comput.5
2023 Enabling Trusted TEE-as-a-Service Models with Privacy Preserving Automatons
abstract
The ideal TEE service model foresees that data owners load their TEE software in an untrusted platform where the specific processing of the business application can take place inside an enclave, shielded against privileged attackers. In this situation, the data owner needs to trust the TEE hardware vendor only. However, it is very common that the enclave software is offered by a third-party that does not share its source code. Therefore, the service provider must be trusted as well. This is not acceptable when privacy requirements are stringent such as in the fintech ecosystem. In this paper, we propose PRIVATON, an approach based on a dual sandbox strategy leveraging TEE technologies with an embedded WebAssembly sandboxed run-time to compute privacy preserving computations modelled as finite state automatons with verifiable proofs of computations. With PRIVATON, the data owner will have the guarantee that even a malicious TEE developer will not be able to get access to the sensitive data. An implementation of PRIVATON was evaluated in the case study provided by the Credora company who is playing the role of a distributed and privacy-preserving credit oracle in the ecosystem of cryptocurrencies trading.
Bala Subramanyan, Arne Hollum, Giovanni Mazzeo, Matthew Ficke, Darshan Vaydia
CloudCom3
2022 PriSIEM: Enabling privacy-preserving Managed Security Services
Luigi Coppolino, Salvatore D'Antonio, Giovanni Mazzeo, Luigi Romano, Luigi Sgaglione
J. Netw. Comput. Appl.3
2022 SGXTuner: Performance Enhancement of Intel SGX Applications Via Stochastic Optimization
abstract
IntelSGXhas started to be widely adopted. Cloud providers (Microsoft Azure, IBM Cloud, Alibaba Cloud) are offering new solutions, implementingdata-in-useprotection via SGX. A major challenge faced by both academia and industry is providing transparent SGX support to legacy applications. The approach with the highest consensus is linking the target software with SGX-extendedlibclibraries. Unfortunately, the increased security entails a dramatic performance penalty, which is mainly due to the intrinsic overhead of context switches, and the limited size of protected memory. Performance optimization is non-trivial since it depends on key parameters whose manual tuning is a very long process. We present the architecture of an automated tool, calledSGXTuner, which is able to find the best setting of SGX-extendedlibclibrary parameters, by iteratively adjusting such parameters based on continuous monitoring of performance data. The tool is — to a large extent — algorithm agnostic. We decided to base the current implementation on a particular type of stochastic optimization algorithm, specificallySimulated Annealing. A massive experimental campaign was conducted on a relevant case study. Three client-server applications —Memcached,Redis, andApache— were compiled with SCONE'ssgx-musland tuned for best performance. Results demonstrate the effectiveness ofSGXTuner.
Giovanni Mazzeo, Sergei Arnautov, Christof Fetzer, Luigi Romano
IEEE Trans. Dependable Secur. Comput.1
2021 Privacy-Preserving Credit Scoring via Functional Encryption
Lorenzo Andolfo, Luigi Coppolino, Salvatore D'Antonio, Giovanni Mazzeo, Luigi Romano, Matthew Ficke, Arne Hollum, Darshan Vaydia
ICCSA (8)4
2021 Enhancing random forest classification with NLP in DAMEH: A system for DAta Management in eHealth Domain
abstract
The use of pervasive IoT devices in Smart Cities, have increased the Volume of data produced in many and many field. Interesting and very useful applications grow up in number in E-health domain, where smart devices are used in order to manage huge amount of data, in highly distributed environments, in order to provide smart services able to collect data to fill medical records of patients. The problem here is to gather data, to produce records and to analyze medical records depending on their contents. Since data gathering involve very different devices (not only wearable medical sensors, but also environmental smart devices, like weather, pollution and other sensors) it is very difficult to classify data depending their contents, in order to enable better management of patients. Data from smart devices couple with medical records written in natural language: we describe here an architecture that is able to determine best features for classification, depending on existent medical records. The architecture is based on pre-filtering phase based on Natural Language Processing, that is able to enhance Machine learning classification based on Random Forests. We carried on experiments on about 5000 medical records from real (anonymized) case studies from various health-care organizations in Italy. We show accuracy of the presented approach in terms of Accuracy-Rejection curves.
Flora Amato, Luigi Coppolino, Giovanni Cozzolino, Giovanni Mazzeo, Francesco Moscato 0001, Roberto Nardone
Neurocomputing4
2021 VISE: Combining Intel SGX and Homomorphic Encryption for Cloud Industrial Control Systems
abstract
Protecting data-in-use from privileged attackers is challenging. New CPU extensions (notably: Intel SGX) and cryptographic techniques (specifically: Homomorphic Encryption) can guarantee privacy even in untrusted third-party systems. HE allows sensitive processing on ciphered data. However, it is affected by i) a dramatic ciphertext expansion making HE unusable when bandwidth is narrow, ii) unverifiable conditional variables requiring off-premises support. Intel SGX allows sensitive processing in a secure enclave. Unfortunately, it is i) strictly bonded to the hosting server making SGX unusable when the live migration of cloud VMs/Containers is desirable, ii) limited in terms of usable memory, which is in contrast with resource-consuming data processing. In this article, we propose the VIrtual Secure Enclave (VISE), an approach that effectively combines the two aforementioned techniques, to overcome their limitations and ultimately make them usable in a typical cloud setup. VISE moves the execution of sensitive HE primitives (e.g., encryption) to the cloud in a remotely attested SGX enclave, and then performs sensitive processing on HE data-outside the enclave-leveraging all the memory resources available. We demonstrate that VISE meets the challenging security and performance requirements of a substantial application in the Industrial Control Systems domain. Our experiments prove the practicability of the proposed solution.
Luigi Coppolino, Salvatore D'Antonio, Valerio Formicola, Giovanni Mazzeo, Luigi Romano
IEEE Trans. Computers4
2019 Privacy Preserving Intrusion Detection Via Homomorphic Encryption
abstract
In the recent years, we are assisting to an undiminished, and unlikely to stop number of cyber threats, that have increased the organizations/companies interest about security concerns. Further, the rising costs of an efficient IT security staff and environment is posing a significant challenge. These have created a new fast growing trend named Managed Security Services (MSS). Often customers turn to MSS providers to alleviate the pressures they face daily related to information security. One of the most critical aspect, related to the outsourcing of security issues, is privacy. Security monitoring and in general security services require access to as much data as possible, in order to provide an effective and reliable service. It is the well known conflict between privacy and security, a particularly evident problem in security monitoring solutions. This paper analyzes a scenario of MSS in order to provide a privacy preserving solution that allows the security monitoring without violating the privacy requirements. The basic idea relies on the usage of the Homomorphic Encryption technology. Encrypting data using homomorphic schemes, cloud computing and MSS providers can perform different computations on encrypted data without ever having access to their decryption. This solution keeps data confidential and secured, not only during exchange and storage, but also during processing. We provide an ad-hoc Intrusion Detection System architecture for privacy preserving security monitoring, considering as counter threats Code Injection attacks on homomorphically encrypted fields.
Luigi Sgaglione, Luigi Coppolino, Salvatore D'Antonio, Giovanni Mazzeo, Luigi Romano, Domenico Cotroneo, Andrea Scognamiglio
WETICE4
2019 A comparative analysis of emerging approaches for securing java software with Intel SGX
Luigi Coppolino, Salvatore D'Antonio, Giovanni Mazzeo, Luigi Romano
Future Gener. Comput. Syst.3
2018 An Approach for Securing Critical Applications in Untrusted Clouds
abstract
The cloud computing has recently emerged as compelling paradigm for managing and delivery services over the internet. However, users as well as critical infrastructure operators, have legitimate concerns about the confidentiality, integrity and availability, in short the dependability, of applications and their data hosted on a third-party cloud. The dependability is become a commercial imperative for cloud providers, especially to support cloud computing for critical infrastructures. In this paper the SecureCloud project, its approach and goals are presented. SecureCloud aims to remove technical impediments to dependable cloud computing, encouraging and enabling a greater uptake of cost-effective, environment-friendly, and innovative cloud solutions, in particular, for critical infrastructure applications.
Luigi Coppolino, Salvatore D'Antonio, Giovanni Mazzeo, Gaetano Papale, Luigi Sgaglione, Ferdinando Campanile
PDP3
2018 Hardening ROS via Hardware-assisted Trusted Execution Environment
abstract
In recent years, humanoid robots have become quite ubiquitous finding wide applicability in many different fields, spanning from education to entertainment and assistance. They can be considered as more complex cyber-physical systems (CPS) and, as such, they are exposed to the same vulnerabilities. This can be very dangerous for people acting that close with these robots, since attackers by exploiting their vulnerabilities, can not only violate people's privacy, but, more importantly, they can command the robot behavior causing them bodily harm, thus leading to devastating consequences. In this paper, we propose a solution not yet investigated in this field, which relies on the use of secure enclaves, which in our opinion could represent a valuable solution for coping with most of the possible attacks, while suggesting developers to adopt such a precaution during the robot design phase.
Mariacarla Staffa, Giovanni Mazzeo, Luigi Sgaglione
RO-MAN2
2018 An OpenNCP-based Solution for Secure eHealth Data Exchange
Mariacarla Staffa, Luigi Sgaglione, Giovanni Mazzeo, Luigi Coppolino, Salvatore D'Antonio, Luigi Romano, Erol Gelenbe, Oana Stan, Sergiu Carpov, Evangelos Grivas, Paolo Campegiani, Luigi Castaldo, Konstantinos Votis, Vassilis Koutkias, Ioannis Komnios
J. Netw. Comput. Appl.3
2017 Integrating Reactive Cloud Applications in SERECA
abstract
A consolidated trend in designing cloud-based applications is to make use of a reactive microservice architecture, which allows to divide an application in several well-partitioned software units with specific responsibilities. Such an architecture perfectly fits in cloud environments, ensuring a number of advantages (i.e., high availability and scalability, ease of deployment and development). However, the new way of designing cloud applications introduces challenging security threats. Besides the difficulty in monitoring security of the overall distributed application, an important aspect of concern relates to the risk of break the chain of trust established among the different microservices belonging to the application. That is, a compromised single microservice may bring down the other related ones.
Christof Fetzer, Giovanni Mazzeo, John Oliver, Luigi Romano, Martijn Verburg
ARES2
2017 Secure Cloud Micro Services Using Intel SGX
Stefan Brenner, Tobias Hundt, Giovanni Mazzeo, Rüdiger Kapitza
DAIS3
2017 Cloudifying Critical Applications: A Use Case from the Power Grid Domain
abstract
The cloud computing paradigm is gaining more and more momentum, to the extent that it is no more confined to its initial application domains, i.e. use by enterprises and businesses that are simply willing to lower costs or to increase computing capacity in a flexible manner. In particular, increasing interest is recently being paid to the dramatic potentials that the use of cloud computing technology by critical infrastructure (CI) operators might bring about, in terms of benefits for the society at large. Since accidental or deliberate damage to a CI may result in devastating consequences, this mandates for dependable and trustworthy security mechanisms in cloud platforms. In this paper, we present a distributed application for real-Time monitoring of a Power Grid. The application, which is called PoGriMon, is deployed on top of the SecureCloud platform, a security-enhanced IaaS solution that exploits the Intel Software Guard eXtension (SGX) technology. PoGriMon has been designed based on the requirements of the SCADA network of the Israeli Electric Corporation (IEC), and it is currently being validated in a realistic setup also provided by IEC.
Ferdinando Campanile, Luigi Coppolino, Salvatore D'Antonio, Leonid Lev, Giovanni Mazzeo, Luigi Romano, Luigi Sgaglione, Francesco Tessitore
PDP5
2016 Direct Debit Frauds: A Novel Detection Approach
abstract
Single Euro Payments Area (SEPA) is an initiative of the European banking industry aiming at making all electronic payments across the Euro area as easy as domestic payments currently are. One of the payment schemes defined by the SEPA mandate is the SEPA Direct Debit (SDD) that allows a creditor (biller) to collect directly funds from a debtor’s (payer’s) account. It is apparent that the use of this standard scheme facilitates the access to new markets by enterprises and public administrations and allows for a substantial cost reduction. However, the other side of the coin is represented by the security issues concerning this type of electronic payments. A study conducted by Center of Economics and Business Research (CEBR) of Britain showed that from 2006 to 2010 the Direct Debit frauds have increased of 288%. In this paper a comprehensive analysis of real SDD data provided by the EU FP7 LeanBigData project is performed. The results of this data analysis will conduct to define emerging attack patterns that can be execute against SDD and the related effective detection criteria. All the work aims at inspire the design of a security system supporting analysts to detect Direct Debit frauds.
Gaetano Papale, Luigi Sgaglione, Gianfranco Cerullo, Giovanni Mazzeo, Pasquale Starace, Ferdinando Campanile
CLOSER (1)4
2016 Data Collection Framework - A Flexible and Efficient Tool for Heterogeneous Data Acquisition
abstract
The data collection for eventual analysis is an old concept that today receives a revisited interest due to the emerging of new research trend such Big Data. Furthermore, considering that a current market trend is to provide integrated solution to achieve multiple purposes (such as ISOC, SIEM, CEP, etc.), the data became very heterogeneous. In this paper a flexible and efficient solution about the data collection of heterogeneous data is presented, describing the approach used to collect heterogeneous data and the additional features (pre-processing) provided with it.
Luigi Sgaglione, Gaetano Papale, Giovanni Mazzeo, Gianfranco Cerullo, Pasquale Starace, Ferdinando Campanile
CLOSER (1)3
2016 A Secure Cloud-Based SCADA Application: The Use Case of a Water Supply Network
abstract
Cloud computing paradigm is gaining more and more momentum, to the extent that it is no more confined to its initial application domains, i.e. use by enterprises and businesses willing to lower costs or to increase computing capacity in a flexible manner. In particular, increasing interest is recently being paid to the huge potentials – in terms of benefits for the society at large – that might result from the adoption of cloud computing technology by critical infrastructure (CI) operators. This is of course putting special emphasis on the need for dependable and trustworthy security mechanisms in cloud technology based services, since a critical infrastructure is vital for essential functioning of a country. Incidental or deliberate damages to a CI have serious impacts on the economy, and possibly make essential services unavailable to the communities it serves. In this paper we present the proof-of concept of a cloud-based Water Supply Network Monitoring (WSNM) application, named RiskBuster (RB), that ensures the confidentiality and integrity of SCADA monitoring data collected from dam sensors and stored in the cloud by using the innovative Intel Software Guard eXtension (SGX) technology.
Gianfranco Cerullo, Giovanni Mazzeo, Gaetano Papale, Luigi Sgaglione, Rosario Cristaldi
SoMeT2